A new technique by cybercriminals: They transfer victims' card information to their own phones
ESET has discovered Android malware that relays NFC traffic to steal money from victims' accounts via ATMs.
ESET researchers have uncovered a cybercriminal campaign targeting customers of three Czech banks. The attackers combined techniques involving social engineering, phishing, and Android malware in a new attack scenario.
ESET believes that messages impersonating Czech banks were sent to random mobile customers in the Czech Republic, and as a result, they managed to ensnare customers of three banks. By copying NFC data from the victims' physical payment cards and relaying this data to the attacker's device, the attackers were able to emulate the original card and withdraw money from an ATM.
The malware, which ESET named NGate, has the unique ability to relay data from victims' payment cards to the attacker's rooted Android phone via a malicious application installed on the victims' Android devices. The primary goal of the criminal campaign is to facilitate unauthorized ATM withdrawals from the victims' bank accounts. This illegal transaction was carried out by relaying near-field communication (NFC) data from the victims' physical payment cards to the attacker's device using the NGate Android malware on compromised Android smartphones. The attacker then used this data to perform ATM transactions. It was also determined that the attacker had a backup plan to transfer money from the victims' accounts to other bank accounts in case this method failed.
Lukáš Štefanko, who discovered the new threat and technique, said, "We have not seen this new NFC relay technique in any previously discovered Android malware. The technique is based on a tool called NFCGate, designed by students at the Technical University of Darmstadt in Germany to capture, analyze, or modify NFC traffic; therefore, we named this new malware family NGate." Victims were deceived into thinking they were communicating with their banks and that their devices were at risk, leading them to download and install the malware. In reality, the victims unknowingly compromised their own Android devices by downloading and installing an application from a link in a deceptive SMS message regarding a potential tax refund.
NGATE WAS NEVER ON THE OFFICIAL GOOGLE PLAY STORE
The NGate Android malware is linked to the phishing activities of a threat actor operating in the Czech Republic since November 2023. However, ESET believes these activities were suspended following the arrest of a suspect in March 2024. ESET Research first noticed the threat actor targeting customers of leading Czech banks at the end of November 2023. The malware was delivered via short-lived domains that mimicked legitimate banking websites or official mobile banking applications found on the Google Play store. These fake domains were detected through the ESET Brand Intelligence Service, which enables the monitoring of threats targeting a client's brand. Within the same month, ESET notified its customers of the findings.
As reported in a previous ESET publication, the attackers exploited the potential of progressive web apps (PWAs) but later improved their strategy by using a more sophisticated version of PWAs known as WebAPKs. Eventually, the operation culminated in the distribution of the NGate malware.
ESET Research discovered in March 2024 that the NGate Android malware became available on the same distribution domains previously used to facilitate phishing campaigns that delivered malicious PWAs and WebAPKs. Once installed and opened, NGate displays a fake website requesting the user's banking credentials, which are then sent to the attacker's server.
In addition to its phishing capabilities, the NGate malware comes with a tool called NFCGate, which is abused to relay NFC data between two devices (the victim's device and the perpetrator's device). Some of these features only work on rooted devices, but in this case, it is possible to relay NFC traffic from non-rooted devices as well. NGate also asks its victims to enter sensitive information such as bank customer IDs, dates of birth, and the PIN codes of their bank cards. It also requests that they turn on the NFC feature on their smartphones and then instructs the victims to place their payment cards on the back of their smartphones until the malicious application recognizes the card.
In addition to the technique used by the NGate malware, an attacker with physical access to payment cards could potentially copy and emulate them. This technique could be used by an attacker attempting to read cards through unattended bags, wallets, backpacks, or smartphone cases where cards are kept, especially in public and crowded places. However, this scenario is generally limited to making small contactless payments at terminal points.
News Source: 12punto
Most Read
Historic words from Özgür Özel at the CHP group meeting
Air Force Academy student Veli Bilgin has died
Striking picture for Özgür Özel's 'New Party'
The PKK opening and Özgür Özel’s path!..
How did the newspapers view Özgür Özel's farewell to the CHP?
He killed his wife by slitting her throat: Their children witnessed the moments
Tuncer Bakırhan calls for a framework law
Here are the names that will be in Özgür Özel's new party!
What did the CHP do?
AKP mayor held responsible